CVE-2020-3161: Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.
Other sources
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco IP Phones vulnerability?
The vulnerability ID for this Cisco IP Phones vulnerability is CVE-2020-3161.
What is the severity level of CVE-2020-3161?
CVE-2020-3161 has a severity level of 9.8 (Critical).
Who is affected by the Cisco IP Phones vulnerability?
The Cisco IP Phones vulnerability affects Cisco IP Phones with specific firmware versions.
What is the impact of CVE-2020-3161?
CVE-2020-3161 can allow an unauthenticated remote attacker to execute code with root privileges or cause a denial-of-service (DoS) condition on an affected Cisco IP Phone.
How can I fix the Cisco IP Phones vulnerability?
To fix the Cisco IP Phones vulnerability, users should update the firmware of their Cisco IP Phones to a non-vulnerable version.